Email security surveys love one number: SPF adoption. By that number, Europe looks done — of the 18,804,722 mail-carrying, active domains we observe, 81.9% publish an SPF record. Compliance checklists get ticked. Deliverability consultants move on.
But an SPF record is a sentence, and the sentence has an ending. It either ends in -all —
"reject mail that fails" — or in ~all — "flag it, deliver it anyway, someone else's
problem." Measured on live DNS, only 29.4% of Europe's mail-carrying
domains publish the reject ending. 47.3% publish soft-fail: the spoofed mail
still arrives, wearing a warning label most mail clients never show.
Per market, the two numbers tell opposite stories. Italy publishes SPF on 88.8% of its mail-carrying domains and rejects on 22.1% — the second-weakest enforcement on this chart, and roughly one publisher in four. Denmark and Sweden publish least (67.8% and 69.6%) but their publishers enforce at the highest rates on the continent — Sweden rejects on 40.4% of all its mail-carrying domains, nearly three in five of the ones that publish anything. Poland leads both axes.
Soft-fail is the safe default of the entire onboarding chain. Hosting panels generate ~all
so a customer's newsletter never bounces during setup. Consultants recommend ~all "for the
transition" — and the transition never ends, because nothing breaks. That is exactly the problem:
a policy that never breaks anything also never blocks anything.
The countries that enforce are instructive. Poland's 53.4% and Sweden's publisher-enforcement rate don't come from stricter businesses — they come from national provider defaults and registrar practice. Email enforcement is an infrastructure-supply property before it is a customer-demand property. Which is also the commercial point: the operator who flips their default moves their whole book up this chart.
The receivers already flipped the switch. Since 2024, Google and Yahoo reject or junk bulk mail that fails authentication — the era of "flag it and deliver anyway" is ending on the receiving side regardless of what senders publish. A hosting book full of soft-fail customers is a book whose newsletters and invoices are drifting toward spam folders: deliverability incidents, support tickets, and churn that lands on the operator's P&L, not the customer's security budget.
Spoofing is the loss line, not the hypothetical. Business email compromise — the fraud that weak
enforcement invites — is consistently among the largest cyber-loss categories insurers pay out. A domain
publishing ~all is a domain any attacker can impersonate with mail that most receivers still
deliver. For insurers and lenders, the enforcement share of a book is an underwritable, portfolio-level
risk number; adoption percentages are not (everyone's is ~80%).
For hosting operators, this is a rare differentiator that isn't price. Enforcement is an infrastructure-supply property — the operator who ships reject-on-fail defaults plus DMARC setup and authentication monitoring moves the whole book up this chart, cuts their own deliverability support load, and sells protection into a base that increasingly has to buy it anyway. We benchmark posture per operator book, so the gap to peers is a number, not a pitch.
-all; soft-fail
~all = 47.3% of Europe's mail-carrying domains.
DMARC, now measured. Earlier versions of this brief said DMARC adoption was not yet collected. It
is — read from _dmarc.<domain>, not from the apex — and it widens the enforcement gap
rather than closing it: 49.8% of Europe's mail-carrying domains publish a DMARC
record, but only 9.4% publish a reject policy. The rest monitor or
quarantine, which is the same "flag it, deliver it" posture one layer up. Separately,
58,430 European domains carry a DMARC record misplaced at the apex
instead of _dmarc — a misconfiguration tally, not adoption, and it is added to neither
figure. Domain-level, aggregate-only; per-operator posture lives in the product.Every figure here is queryable through the HostingBrain connector. In Claude or any MCP-compatible assistant, this is the whole brief in one prompt:
“Using HostingBrain, compare SPF adoption versus SPF hard-fail enforcement across European markets — Europe overall, then Poland, Italy, Sweden and Germany. Which markets publish but don't enforce?”
Resolves to email_security (free). See definitions('spf_posture').
Reproduce this analysis: the email_security
tool returns adoption, hard-fail and soft-fail shares for every market above — free tier. Per-operator
posture: email_security(operator=...) (Pro).
Ask the follow-up yourself. HostingBrain answers questions like this — with the date, denominator and caveats attached — inside Claude and any MCP-compatible assistant.